PT-2020-19374 · Cacti+2 · Cacti+2

0Xfatty

·

Published

2020-01-16

·

Updated

2025-01-24

·

CVE-2020-7106

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cacti version 1.2.8
Description The issue concerns stored XSS in several PHP files, including data sources.php, color templates item.php, graphs.php, graph items.php, lib/api automation.php, user admin.php, and user group admin.php. This is demonstrated by the description parameter in data sources.php, where a raw string from the database is displayed by $header, triggering the XSS.
Recommendations For Cacti version 1.2.8, consider disabling the affected PHP files or restricting access to them until a patch is available. As a temporary workaround, avoid using the description parameter in the affected files to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1488
ALT-PU-2020-3430
ALT-PU-2025-1813
CVE-2020-7106
DLA-2069-1
DLA-2965-1
OPENSUSE-SU-2020:0272-1
OPENSUSE-SU-2020:0284-1
OPENSUSE-SU-2020:0558-1
OPENSUSE-SU-2020:0565-1
OPENSUSE-SU-2020:0654-1
OPENSUSE-SU-2020_0272-1
OPENSUSE-SU-2020_0558-1
OPENSUSE-SU-2020_0654-1
OPENSUSE-SU-2024:10670-1

Affected Products

Alt Linux
Cacti
Suse